<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Redirect http and https traffic from ASA 5520 via squid in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/redirect-http-and-https-traffic-from-asa-5520-via-squid/m-p/1617734#M596330</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The ASA can only redirect HTTP/HTTPs traffic to a websense or secure computing smartfilter (owned by McAfee).&amp;nbsp; I had a client that used squid for a proxy and they used a GPO or script to force a browser to use it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 21 Dec 2010 14:30:16 GMT</pubDate>
    <dc:creator>deyster94</dc:creator>
    <dc:date>2010-12-21T14:30:16Z</dc:date>
    <item>
      <title>Redirect http and https traffic from ASA 5520 via squid</title>
      <link>https://community.cisco.com/t5/network-security/redirect-http-and-https-traffic-from-asa-5520-via-squid/m-p/1617733#M596329</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Right now, in my network there is no proxy server and all users go straight through the ASA to access internet. I would like to put a squid with dansguardian (for web filtering). Can someone guide me the steps in getting all http and https traffic from ASA go via my squid? Any help greatly appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ribin&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 19:25:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/redirect-http-and-https-traffic-from-asa-5520-via-squid/m-p/1617733#M596329</guid>
      <dc:creator>ribin.jones</dc:creator>
      <dc:date>2019-03-11T19:25:47Z</dc:date>
    </item>
    <item>
      <title>Re: Redirect http and https traffic from ASA 5520 via squid</title>
      <link>https://community.cisco.com/t5/network-security/redirect-http-and-https-traffic-from-asa-5520-via-squid/m-p/1617734#M596330</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The ASA can only redirect HTTP/HTTPs traffic to a websense or secure computing smartfilter (owned by McAfee).&amp;nbsp; I had a client that used squid for a proxy and they used a GPO or script to force a browser to use it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Dec 2010 14:30:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/redirect-http-and-https-traffic-from-asa-5520-via-squid/m-p/1617734#M596330</guid>
      <dc:creator>deyster94</dc:creator>
      <dc:date>2010-12-21T14:30:16Z</dc:date>
    </item>
    <item>
      <title>Re: Redirect http and https traffic from ASA 5520 via squid</title>
      <link>https://community.cisco.com/t5/network-security/redirect-http-and-https-traffic-from-asa-5520-via-squid/m-p/1617735#M596331</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I certainly believe that we can redirect traffic via squid. I have seen some posts which does this using wccp.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My current config is below:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;access-list wccp-servers permit ip host 192.168.40.201 any&lt;BR /&gt;access-list wccp-traffic permit ip 192.168.40.0 255.255.255.0 any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;wccp web-cache group-list wccp-servers redirect-list wccp-traffic&lt;BR /&gt;wccp interface Management web-cache redirect in&lt;BR /&gt;wccp interface inside web-cache redirect in&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;192.168.40.201 is my proxy server ip&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But I think there is nothing happening in the ASA:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA(config)# sh wccp interfaces&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;WCCP interface configuration:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; GigabitEthernet0/1&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Output services: 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Input services:&amp;nbsp; 1&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Mcast services:&amp;nbsp; 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Exclude In:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; FALSE&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Management0/0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Output services: 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Input services:&amp;nbsp; 1&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Mcast services:&amp;nbsp; 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Exclude In:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; FALSE&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA(config)# sh wccp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Global WCCP information:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Router information:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Router Identifier:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -not yet determined-&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Protocol Version:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Service Identifier: web-cache&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Number of Cache Engines:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Number of routers:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Total Packets Redirected:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Redirect access-list:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; wccp-traffic&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Total Connections Denied Redirect:&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Total Packets Unassigned:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Group access-list:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; wccp-servers&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Total Messages Denied to Group:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Total Authentication failures:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Total Bypassed Packets Received:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Ribin&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Ribin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Dec 2010 14:54:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/redirect-http-and-https-traffic-from-asa-5520-via-squid/m-p/1617735#M596331</guid>
      <dc:creator>ribin.jones</dc:creator>
      <dc:date>2010-12-21T14:54:58Z</dc:date>
    </item>
    <item>
      <title>Re: Redirect http and https traffic from ASA 5520 via squid</title>
      <link>https://community.cisco.com/t5/network-security/redirect-http-and-https-traffic-from-asa-5520-via-squid/m-p/1617736#M596332</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Fair enough.&amp;nbsp; Not having implemented WCCP on the ASA, I can't be of help with this.&amp;nbsp; However, a quick google search came up with this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://parvinderbhasin.blogspot.com/2009/06/squid-wccp-and-cisco-asa-setup.html"&gt;http://parvinderbhasin.blogspot.com/2009/06/squid-wccp-and-cisco-asa-setup.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Dec 2010 15:00:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/redirect-http-and-https-traffic-from-asa-5520-via-squid/m-p/1617736#M596332</guid>
      <dc:creator>deyster94</dc:creator>
      <dc:date>2010-12-21T15:00:25Z</dc:date>
    </item>
    <item>
      <title>Re: Redirect http and https traffic from ASA 5520 via squid</title>
      <link>https://community.cisco.com/t5/network-security/redirect-http-and-https-traffic-from-asa-5520-via-squid/m-p/1617737#M596333</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yep...I did the configuration using the same url. Thanks for your time.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can some one see whether there is any issue with my wccp configuration?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Ribin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Dec 2010 15:04:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/redirect-http-and-https-traffic-from-asa-5520-via-squid/m-p/1617737#M596333</guid>
      <dc:creator>ribin.jones</dc:creator>
      <dc:date>2010-12-21T15:04:23Z</dc:date>
    </item>
    <item>
      <title>Re: Redirect http and https traffic from ASA 5520 via squid</title>
      <link>https://community.cisco.com/t5/network-security/redirect-http-and-https-traffic-from-asa-5520-via-squid/m-p/1617738#M596334</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV&gt;&lt;P&gt;I see two redirect interfaces&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;wccp web-cache group-list wccp-servers redirect-list wccp-traffic&lt;BR /&gt;wccp interface Management web-cache redirect in&lt;BR /&gt;wccp interface inside web-cache redirect in &lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Where are your host browsing? Behind what interface?&lt;/P&gt;&lt;P&gt;Your hosts need to be behind the same interface as the wccp engine, that is a requirement &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope it helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PK&lt;/P&gt;&lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Dec 2010 23:25:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/redirect-http-and-https-traffic-from-asa-5520-via-squid/m-p/1617738#M596334</guid>
      <dc:creator>Panos Kampanakis</dc:creator>
      <dc:date>2010-12-21T23:25:40Z</dc:date>
    </item>
    <item>
      <title>Re: Redirect http and https traffic from ASA 5520 via squid</title>
      <link>https://community.cisco.com/t5/network-security/redirect-http-and-https-traffic-from-asa-5520-via-squid/m-p/1617739#M596335</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;All hosts are in 192.168.40.0/24 network and my proxy server is also in 40 n/w.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Ribin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Dec 2010 03:54:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/redirect-http-and-https-traffic-from-asa-5520-via-squid/m-p/1617739#M596335</guid>
      <dc:creator>ribin.jones</dc:creator>
      <dc:date>2010-12-22T03:54:48Z</dc:date>
    </item>
    <item>
      <title>Re: Redirect http and https traffic from ASA 5520 via squid</title>
      <link>https://community.cisco.com/t5/network-security/redirect-http-and-https-traffic-from-asa-5520-via-squid/m-p/1617740#M596336</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;My scenario is like below:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Users (in 192.168.40.0/24 n/w) ------- Layer 3 switch(default g/w of all traffic is 192.168.30.1) ------------(192.168.30.8) ASA--------Internet&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Management interface IP of ASA is 192.168.40.8 and inside interface IP is 192.168.30.8. Squid server is connected in Layer 3 switch with IP 192.168.40.201. All users are in 192.168.40.0/24 n/w.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Ribin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Dec 2010 13:42:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/redirect-http-and-https-traffic-from-asa-5520-via-squid/m-p/1617740#M596336</guid>
      <dc:creator>ribin.jones</dc:creator>
      <dc:date>2010-12-22T13:42:45Z</dc:date>
    </item>
    <item>
      <title>Re: Redirect http and https traffic from ASA 5520 via squid</title>
      <link>https://community.cisco.com/t5/network-security/redirect-http-and-https-traffic-from-asa-5520-via-squid/m-p/1617741#M596337</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Your hosts need to be behind the same interface as your squid. The squid needs to be able to send the pages to the hosts directly, not through the ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To begin with I would try just the &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;wccp web-cache redirect-list wccp-traffic&lt;BR /&gt;wccp interface Management web-cache redirect in&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Make sure the management interface has the command "no management-only".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then see if the ASA redirects and if he sees the squid "sh wccp" commands.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope it helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Dec 2010 14:46:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/redirect-http-and-https-traffic-from-asa-5520-via-squid/m-p/1617741#M596337</guid>
      <dc:creator>Panos Kampanakis</dc:creator>
      <dc:date>2010-12-22T14:46:11Z</dc:date>
    </item>
    <item>
      <title>Re: Redirect http and https traffic from ASA 5520 via squid</title>
      <link>https://community.cisco.com/t5/network-security/redirect-http-and-https-traffic-from-asa-5520-via-squid/m-p/1617742#M596338</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My show wccp command output is below:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA(config)# sh wccp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Global WCCP information:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Router information:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Router Identifier:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -not yet determined-&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Protocol Version:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Service Identifier: web-cache&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Number of Cache Engines:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Number of routers:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Total Packets Redirected:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Redirect access-list:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; wccp-traffic&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Total Connections Denied Redirect:&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Total Packets Unassigned:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Group access-list:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; wccp-servers&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Total Messages Denied to Group:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Total Authentication failures:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Total Bypassed Packets Received:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It seems nothing is happening. I did "no management-only command in my management interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Ribin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Dec 2010 11:31:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/redirect-http-and-https-traffic-from-asa-5520-via-squid/m-p/1617742#M596338</guid>
      <dc:creator>ribin.jones</dc:creator>
      <dc:date>2010-12-23T11:31:46Z</dc:date>
    </item>
    <item>
      <title>Re: Redirect http and https traffic from ASA 5520 via squid</title>
      <link>https://community.cisco.com/t5/network-security/redirect-http-and-https-traffic-from-asa-5520-via-squid/m-p/1617743#M596339</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey Ribin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Use route-map to route port 80 (internet) traffic to Squid Proxy Server. Also you need to configure IPtables on squid accordingly (in case of transparent Proxy) Use below configuration on your cisco ASA (i.e. on your gateway). Check whether route-map command is available on your ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list 111 deny&amp;nbsp;&amp;nbsp; tcp any any neq www&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (create access list for port 80 traffic)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list 111 deny&amp;nbsp;&amp;nbsp; tcp host 192.168.100.1 any&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (192.168.100.1&amp;nbsp; - squid proxy)&lt;/P&gt;&lt;P&gt;access-list 111 permit tcp any any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;route-map proxy-redirect permit 100&lt;/P&gt;&lt;P&gt; match ip address 111&lt;/P&gt;&lt;P&gt; set ip next-hop 192.168.100.1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (forward all port 80 traffic to squid- 192.168.100.1)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers!!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Jan 2011 11:02:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/redirect-http-and-https-traffic-from-asa-5520-via-squid/m-p/1617743#M596339</guid>
      <dc:creator>ssantosh1978</dc:creator>
      <dc:date>2011-01-05T11:02:00Z</dc:date>
    </item>
    <item>
      <title>Re: Redirect http and https traffic from ASA 5520 via squid</title>
      <link>https://community.cisco.com/t5/network-security/redirect-http-and-https-traffic-from-asa-5520-via-squid/m-p/1617744#M596340</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Santhosh,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, route-map command is available in my ASA. Can I do the similar configuration in my Layer 3 switch? My L3 switch has ipservices ios and it supports route-map commands, rather than doing this in ASA?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Ribin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Jan 2011 15:19:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/redirect-http-and-https-traffic-from-asa-5520-via-squid/m-p/1617744#M596340</guid>
      <dc:creator>ribin.jones</dc:creator>
      <dc:date>2011-01-05T15:19:10Z</dc:date>
    </item>
    <item>
      <title>Re: Redirect http and https traffic from ASA 5520 via squid</title>
      <link>https://community.cisco.com/t5/network-security/redirect-http-and-https-traffic-from-asa-5520-via-squid/m-p/1617745#M596341</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Ribin&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes you can use route-map on your switch (but switch needs to be gateway for your network). I am using route map on my cisco 3750 series switch with Squid which is acting as gateway for my network... Let me know if you have any issues.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers!!!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Jan 2011 10:23:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/redirect-http-and-https-traffic-from-asa-5520-via-squid/m-p/1617745#M596341</guid>
      <dc:creator>ssantosh1978</dc:creator>
      <dc:date>2011-01-06T10:23:26Z</dc:date>
    </item>
    <item>
      <title>Re: Redirect http and https traffic from ASA 5520 via squid</title>
      <link>https://community.cisco.com/t5/network-security/redirect-http-and-https-traffic-from-asa-5520-via-squid/m-p/1617746#M596342</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I will give it a try today and let u know....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Ribin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Jan 2011 07:33:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/redirect-http-and-https-traffic-from-asa-5520-via-squid/m-p/1617746#M596342</guid>
      <dc:creator>ribin.jones</dc:creator>
      <dc:date>2011-01-07T07:33:53Z</dc:date>
    </item>
    <item>
      <title>Re: Redirect http and https traffic from ASA 5520 via squid</title>
      <link>https://community.cisco.com/t5/network-security/redirect-http-and-https-traffic-from-asa-5520-via-squid/m-p/1617747#M596343</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey Santhosh,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just a final review before I try this. My scenario is like below:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Users (in 192.168.40.0/24 n/w) ------- Layer 3 with vlan's 40 and 30(default g/w of all&amp;nbsp; traffic is 192.168.30.1 which is ASA's inside IP) ------------(192.168.30.8) ASA--------Internet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Users and proxy server (192.168.40.201) are in the same vlan 40. Where do I need to apply the policy map? I hope it is in vlan 40 in my layer 3 switch, right?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Ribin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Jan 2011 08:45:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/redirect-http-and-https-traffic-from-asa-5520-via-squid/m-p/1617747#M596343</guid>
      <dc:creator>ribin.jones</dc:creator>
      <dc:date>2011-01-07T08:45:38Z</dc:date>
    </item>
    <item>
      <title>Re: Redirect http and https traffic from ASA 5520 via squid</title>
      <link>https://community.cisco.com/t5/network-security/redirect-http-and-https-traffic-from-asa-5520-via-squid/m-p/1617748#M596344</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It worked great ... Thank you Santhosh and others.....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Ribin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Jan 2011 14:22:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/redirect-http-and-https-traffic-from-asa-5520-via-squid/m-p/1617748#M596344</guid>
      <dc:creator>ribin.jones</dc:creator>
      <dc:date>2011-01-07T14:22:30Z</dc:date>
    </item>
    <item>
      <title>Re: Redirect http and https traffic from ASA 5520 via squid</title>
      <link>https://community.cisco.com/t5/network-security/redirect-http-and-https-traffic-from-asa-5520-via-squid/m-p/1617749#M596345</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Santhosh,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A clarification..What does the first line of below acl does for proxy redirect? I hope it denies all traffic except 80 and redirects 80 traffic to proxy ip?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list 111 deny&amp;nbsp;&amp;nbsp; tcp any any neq www&lt;BR /&gt;access-list 111 deny&amp;nbsp;&amp;nbsp; tcp host 192.168.40.11 any&lt;/P&gt;&lt;P&gt;access-list 111 permit tcp any any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;192.168.40.11 is my proxy ip.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Jan 2011 12:50:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/redirect-http-and-https-traffic-from-asa-5520-via-squid/m-p/1617749#M596345</guid>
      <dc:creator>ribin.jones</dc:creator>
      <dc:date>2011-01-13T12:50:44Z</dc:date>
    </item>
    <item>
      <title>Re: Redirect http and https traffic from ASA 5520 via squid</title>
      <link>https://community.cisco.com/t5/network-security/redirect-http-and-https-traffic-from-asa-5520-via-squid/m-p/1617750#M596346</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey Ribin &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please follow below steps to redirect http traffic to squid..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="active_link" href="http://www.vmwareandme.com/2013/10/guide-how-to-redirect-http-traffic-from_23.html"&gt;http://www.vmwareandme.com/2013/10/guide-how-to-redirect-http-traffic-from_23.html&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 01 Aug 2011 10:39:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/redirect-http-and-https-traffic-from-asa-5520-via-squid/m-p/1617750#M596346</guid>
      <dc:creator>ssantosh1978</dc:creator>
      <dc:date>2011-08-01T10:39:09Z</dc:date>
    </item>
    <item>
      <title>Redirect http and https traffic from ASA 5520 via squid</title>
      <link>https://community.cisco.com/t5/network-security/redirect-http-and-https-traffic-from-asa-5520-via-squid/m-p/1617751#M596347</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes but you apply the route map on your L3 switch, NOT on the ASA. &lt;/P&gt;&lt;P&gt;ASA has not the set ip next hop feature, route maps are only used in routing protocol (RIP, OSPF, etc) redistribution!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Apr 2012 13:56:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/redirect-http-and-https-traffic-from-asa-5520-via-squid/m-p/1617751#M596347</guid>
      <dc:creator>psmidcnss</dc:creator>
      <dc:date>2012-04-11T13:56:34Z</dc:date>
    </item>
  </channel>
</rss>

